IP Library Granted Patent US 9,407,441
Granted Patent B1
US 9,407,441 · App. 13/927,386 · Granted Aug 2, 2016

Adding entropy to key generation on a mobile device

Inventors: Yedidya Dotan (Newton, MA); Lawrence N. Friedman (Arlington, MA); Daniel V. Bailey (Pepperell, MA); John Brainard (Sudbury, MA); William M. Duane (Westford, MA)
Assignee: EMC Corporation
H04L9/3226
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,407,441
App. No.
13/927,386
Filed
Jun 26, 2013
Granted
Aug 2, 2016
Kind
B1
Art Unit
2496
USPC
713/183
Abstract

Methods, apparatus and articles of manufacture for adding entropy to key generation on a mobile device are provided herein. A method includes generating a prompt via a computing device interface in connection with an authentication request to access a protected resource associated with the computing device; processing input cryptographic information entered via the computing device interface in response to the prompt against a pre-determined set of cryptographic information, wherein said pre-determined set of cryptographic information comprises one or more input elements and one or more interface manipulation measures associated with the one or more input elements; and resolving the authentication request based on said processing.

Claims (47)

1. A method comprising:

generating a prompt via a computing device interface in connection with an authentication request to access a protected resource associated with the computing device;

processing input cryptographic information entered via the computing device interface in response to the prompt against a pre-determined set of cryptographic information, wherein said pre-determined set of cryptographic information comprises (i) two or more input elements and (ii) two or more qualitative and/or quantitative interface manipulation measures associated with the action of entering the two or more input elements via the computing device interface, wherein the two or more qualitative and/or quantitative interface manipulation measures comprise at least (a) pace of input and (b) directionality of the manipulation of the computing device interface, and wherein said processing comprises:

re-ordering the two or more input elements after being entered via the computing device interface by mapping the two or more input elements to a unique user via a mapping table stored locally on the computing device so as to identify a re-ordered version of the two or more input elements to be used in combination with the two or more qualitative and/or quantitative interface manipulation measures for granting access to the protected resource associated with the computing device; and

resolving the authentication request based on said processing, wherein said resolving comprises granting access to the protected resource upon a determination that the input cryptographic information matches (i) the two or more input elements of the pre-determined set of cryptographic information and (ii) the two or more qualitative and/or quantitative interface manipulation measures of the pre-determined set of cryptographic information.

2. The method of claim 1 , wherein said input cryptographic information comprises one or more items of authentication information.

3. The method of claim 1 , wherein said pre-determined set of cryptographic information comprises a set of authentication information.

4. The method of claim 1 , wherein said computing device comprises a mobile device.

5. The method of claim 1 , wherein said two or more input elements comprises at least one of a number, a letter, a character, a symbol, an image, and a color.

6. The method of claim 1 , wherein said directionality of a manipulation of the computing device interface comprises swiping of a finger via the interface in at least one of a clockwise direction, a counter-clockwise direction, an upward direction, a downward direction, a leftward direction, and a rightward direction.

7. The method of claim 1 , wherein said two or more qualitative and/or quantitative interface manipulation measures associated with the action of entering the two or more input elements via the computing device interface further comprises a distinct number of iterations of an action in connection with a manipulation of the computing device interface.

8. The method of claim 7 , wherein said a distinct number of iterations of an action comprises a number of rotations of an element of the computing device interface.

9. The method of claim 1 , wherein said two or more qualitative and/or quantitative interface manipulation measures associated with the action of entering the two or more input elements via the computing device interface further comprises velocity of a manipulation of the computing device interface.

10. The method of claim 1 , wherein said resolving further comprises denying access to the protected resource associated with the computing device upon a determination that the input cryptographic information does not match (i) the two or more input elements of the pre-determined set of cryptographic information and (ii) the two or more qualitative and/or quantitative interface manipulation measures of the pre-determined set of cryptographic information.

11. The method of claim 1 , comprising:

hashing a combination of the two or more input elements to utilize data contained therein to introduce additional entropy to said authentication request.

12. The method of claim 1 , comprising:

converting the two or more input elements to a second version of the two or more input elements for granting access to the protected resource associated with the computing device, wherein said converting comprises mapping the two or more input elements to a unique user via a mapping table, and wherein the second version of the two or more input elements introduces at least one additional aspect of complexity.

13. The method of claim 1 , wherein said two or more input elements in said pre-determined set of cryptographic information comprises multiple elements of varying type.

14. An article of manufacture comprising a non-transitory processor-readable storage medium having processor-readable instructions tangibly embodied thereon which, when implemented, cause a processor to:

generate a prompt via a computing device interface in connection with an authentication request to access a protected resource associated with the computing device;

process input cryptographic information entered via the computing device interface in response to the prompt against a pre-determined set of cryptographic information, wherein said pre-determined set of cryptographic information comprises (i) two or more input elements and (ii) two or more qualitative and/or quantitative interface manipulation measures associated with the

action of entering the two or more input elements via the computing device interface, wherein the two or more qualitative and/or quantitative interface manipulation measures comprise at least (a) pace of input and (b) directionality of the manipulation of the computing device interface, and wherein said processing comprises:

re-ordering the two or more input elements after being entered via the computing device interface by mapping the two or more input elements to a unique user via a mapping table stored locally on the computing device so as to identify a re-ordered version of the two or more input elements to be used in combination with the two or more qualitative and/or quantitative interface manipulation measures for granting access to the protected resource associated with the computing device; and

resolve the authentication request based on said processing, wherein said resolving comprises granting access to the protected resource upon a determination that the input cryptographic information matches (i) the two or more input elements of the pre-determined set of cryptographic information and (ii) the two or more qualitative and/or quantitative interface manipulation measures of the pre-determined set of cryptographic information.

15. An apparatus comprising:

a memory; and

at least one processor coupled to the memory and configured to:

generate a prompt via a computing device interface in connection with an authentication request to access a protected resource associated with the computing device;

process input cryptographic information entered via the computing device interface in response to the prompt against a pre-determined set of cryptographic information, wherein said pre-determined set of cryptographic information comprises (i) two or more input elements and (ii) two or more qualitative and/or quantitative interface manipulation measures associated with the action of entering the two or more input elements via the computing device interface, wherein the two or more qualitative and/or quantitative interface manipulation measures comprise at least (a) pace of input and (b) directionality of the manipulation of the computing device interface, and wherein said processing comprises:

re-ordering the two or more input elements after being entered via the computing device interface by mapping the two or more input elements to a unique user via a mapping table stored locally on the computing device so as to identify a re-ordered version of the two or more input elements to be used in combination with the two or more qualitative and/or quantitative interface manipulation measures for granting access to the protected resource associated with the computing device; and

resolve the authentication request based on said processing, wherein said resolving comprises granting access to the protected resource upon a determination that the input cryptographic information matches (i) the two or more input elements of the pre-determined set of cryptographic information and (ii) the two or more qualitative and/or quantitative interface manipulation measures of the pre-determined set of cryptographic information.

16. A method comprising:

generating a prompt via a computing device interface in connection with an authentication request to access a protected resource associated with the computing device;

processing input cryptographic information entered via the computing device interface in response to the prompt against a pre-determined set of cryptographic information, wherein said pre-determined set of cryptographic information comprises (i) two or more input elements and (ii) two or more qualitative and/or quantitative interface manipulation measures associated with the action of entering the two or more input elements via the computing device interface, wherein the two or more qualitative and/or quantitative interface manipulation measures comprise at least (a) pace of input and (b) directionality of the manipulation of the computing device interface, and wherein said processing comprises:

re-ordering the two or more input elements after being entered via the computing device interface by mapping the two or more input elements to a unique user via a mapping table stored locally on the computing device so as to identify a re-ordered version of the two or more input elements to be used in combination with the two or more qualitative and/or quantitative interface manipulation measures for granting access to the protected resource associated with the computing device;

learning a pattern associated with manipulation of the computing device interface in connection with the two or more qualitative and/or quantitative interface manipulation measures over multiple iterations of said processing step to establish two or more updated qualitative and/or quantitative interface manipulation measures associated with the action of entering the two or more input elements via the computing device interface; and

updating the pre-determined set of cryptographic information based on the two or more updated interface manipulation measures.

17. The method of claim 16 , wherein said input cryptographic information comprises one or more items of authentication information.

18. The method of claim 16 , wherein said pre-determined set of cryptographic information comprises a set of authentication information.

19. The method of claim 16 , wherein said two or more qualitative and/or quantitative interface manipulation measures associated with the action of entering the two or more input elements via the computing device interface further comprises a distinct number of iterations of an action in connection with a manipulation of the computing device interface.

20. The method of claim 16 , wherein said two or more qualitative and/or quantitative interface manipulation measures associated with the action of entering the two or more input elements via the computing device interface further comprises velocity of a manipulation of the computing device interface.

21. The method of claim 16 , comprising:

hashing a combination of the two or more input elements to utilize data contained therein to introduce additional entropy to said authentication request.

22. The method of claim 16 , wherein said two or more input elements comprises at least one of a number, a letter, a character, a symbol, an image, and a color.

23. The method of claim 16 , wherein said directionality of a manipulation of the computing device interface comprises swiping of a finger via the interface in at least one of a clockwise direction, a counter-clockwise direction, an upward direction, a downward direction, a leftward direction, and a rightward direction.

24. The method of claim 16 , wherein said computing device comprises a mobile device.

Assignments (18)
RELEASE OF SECURITY INTEREST FILED JANUARY 21, 2026 Recorded Mar 9, 2026
From: ALTER DOMUS (US) LLC
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075089/0201 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2020
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 054277/0579 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2013
From: DOTAN, YEDIDYA; FRIEDMAN, LAWRENCE N.; BAILEY, DANIEL V.; BRAINARD, JOHN; DUANE, WILLIAM M.
To: EMC CORPORATION
Reel/Frame 031091/0476 →